|
246211
|
6.1 |
MEDIUM
Network
|
dilicms
|
dilicms
|
XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_type parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18209
|
2024-11-21 12:55 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246212
|
6.1 |
MEDIUM
Network
|
virtualmin
|
virtualmin
|
Virtualmin 6.03 allows XSS via the query string, as demonstrated by the webmin_search.cgi URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18208
|
2024-11-21 12:55 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246213
|
6.1 |
MEDIUM
Network
|
virtualmin
|
virtualmin
|
Virtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter.
|
CWE-74
Injection
|
CVE-2018-18207
|
2024-11-21 12:55 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246214
|
6.5 |
MEDIUM
Network
|
xiongmaitech
|
xmeye_p2p_cloud_server
|
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumented user account "default" with its default password to login to XMeye and access…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-17919
|
2024-11-21 12:55 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246215
|
5.3 |
MEDIUM
Network
|
xiongmaitech
|
xmeye_p2p_cloud_server
|
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potential Cloud IDs. Using this ID, the attacker can discover and …
|
CWE-200
Information Exposure
|
CVE-2018-17917
|
2024-11-21 12:55 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246216
|
9.8 |
CRITICAL
Network
|
xiongmaitech
|
xmeye_p2p_cloud_server
|
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server do not encrypt all device communication. This includes the XMeye service and firmware update communication. This could all…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2018-17915
|
2024-11-21 12:55 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246217
|
4.8 |
MEDIUM
Local
|
ge
|
ifix
|
Multiple instances of this vulnerability (Unsafe ActiveX Control Marked Safe For Scripting) have been identified in the third-party ActiveX object provided to GE iFIX versions 2.0 - 5.8 by Gigasoft. …
|
NVD-CWE-noinfo
|
CVE-2018-17925
|
2024-11-21 12:55 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246218
|
7.5 |
HIGH
Network
|
bytom
|
bytom
|
In the client in Bytom before 1.0.6, checkTopicRegister in p2p/discover/net.go does not prevent negative idx values, leading to a crash.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-18206
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246219
|
9.8 |
CRITICAL
Network
|
ibm
|
qlogic_4_gb_fibre_channel_expansion_card_firmware qlogic_20-port_4\/8_gb_san_switch_module_firmware
|
The QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 modules for IBM BladeCenter have an undocumented support account with a support password, an undocumented diags account with a diags p…
|
NVD-CWE-noinfo
|
CVE-2018-18202
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246220
|
8.8 |
HIGH
Network
|
qibosoft
|
qibosoft
|
qibosoft V7.0 allows CSRF via admin/index.php?lfj=member&action=addmember to add a user account.
|
CWE-352
Origin Validation Error
|
CVE-2018-18201
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|